CCPA penalties are set per violation, not per case, and that is the arithmetic every California privacy budget has to start from. Since the 2025 inflation adjustment the administrative fine under Civil Code section 1798.155 is up to $2,663 for each violation, or $7,988 for each intentional violation and each violation involving the personal information of a consumer the business knows is under 16; the Attorney General’s civil penalties under section 1798.199.90 carry the same amounts; and the private right of action under section 1798.150 — for data breaches caused by a failure to maintain reasonable security — is $107 to $799 per consumer per incident, or actual damages if greater. The 30-day cure period that softened the original statute was removed on 1 January 2023. The California Privacy Protection Agency has been issuing decisions since 2024, and its largest to date is $1.35 million. This guide sets out the four penalty channels and their amounts, how “per violation” is counted, the Delete Act’s per-day fines that sit beside them, the enforcement record from Honda to the 2026 data broker actions, the conduct the Agency has actually fined, and how to reduce exposure before a complaint arrives.

The four CCPA penalties channels
| Channel | Who brings it | Amount (effective 1 January 2025) | Scope |
|---|---|---|---|
| Administrative fine, Civil Code § 1798.155 | The California Privacy Protection Agency, by decision of its Board after an Enforcement Division investigation and, if contested, an administrative hearing | Up to $2,663 per violation; up to $7,988 per intentional violation or violation involving a consumer known to be under 16 | Any violation of the CCPA or the regulations |
| Civil penalty, § 1798.199.90 | The Attorney General, in a civil action | The same amounts, recovered in court | Any violation of the CCPA or the regulations |
| Private right of action, § 1798.150 | Consumers, individually or as a class | $107 to $799 per consumer per incident, or actual damages, whichever is greater; plus injunctive relief | Only a breach of non-encrypted, non-redacted personal information caused by a failure to implement reasonable security; a 30-day written notice and cure applies to statutory damages claims |
| Delete Act fines, § 1798.99.82 | The Agency | $200 per day for failing to register; $200 per deletion request per day for failing to delete; plus unpaid fees and costs | Data brokers only |
The amounts are indexed: section 1798.199.95 adjusts them every odd-numbered year for the California consumer price index, which is how $2,500 and $7,500 became $2,663 and $7,988, and $100 to $750 became $107 to $799, from 1 January 2025. The next adjustment falls on 1 January 2027. Our guide to CCPA compliance covers the obligations the penalties attach to.
How CCPA penalties are counted per violation
The statute does not define the unit, and the Agency’s decisions show the practical answer: a violation is generally a failure with respect to a consumer or a request, so a broken opt-out mechanism that ran for 40 days is not one violation but one for every Californian whose request failed in the period. The $345,178 Todd Snyder fine in May 2025 was built that way — a misconfigured privacy portal that failed to process opt-out requests for 40 days, plus excessive verification demands — and the Board’s decisions describe the count. The intentional tier and the under-16 tier triple the per-unit amount, which is why children’s data and knowing non-compliance are the two facts that change a settlement’s order of magnitude. The absence of a cure period since 2023 means the count starts on the day of the violation, not the day of the notice.
The CCPA penalties record
| Date | Respondent | Amount | Conduct |
|---|---|---|---|
| November 2024 – January 2025 | Several data brokers | Settlements for failure to register | Delete Act registration |
| 12 March 2025 | American Honda Motor Co. | $632,500 | Excessive verification for opt-out and limit requests; a privacy management tool that did not offer choices symmetrically; obstacles to authorised agents |
| 6 May 2025 | Todd Snyder, Inc. | $345,178 | Privacy portal failed to process opt-outs for 40 days; excess information demanded; verification required for opt-outs |
| 30 September 2025 | Tractor Supply Company | $1,350,000 — the Agency’s largest | No compliant privacy policy; job applicants not notified of their rights; the first decision on applicants’ privacy rights |
| 3 December 2025 | ROR Partners LLC | $56,600 in fines and past-due fees | Marketing firm operating as an unregistered data broker; first case from the Data Broker Enforcement Strike Force |
| 11 August 2026 | LocateSmarter LLC | $116,490 | First decision under both the CCPA and the Delete Act: late registration and demanding partial Social Security numbers before opt-outs |
| 13 August 2026 | Cybba, Inc. | $52,400 | Failure to register by the 2025 deadline; ordered to process requests through DROP |
| 1 September 2026 | SalesIntel Research, Inc. | $36,400 | Failure to register timely; ordered onto DROP |
Two patterns run through the CCPA penalties record. The Agency’s CCPA cases have concentrated on the mechanics of consumer rights — opt-outs that do not work, verification demanded where the statute forbids it, notices missing for a population such as applicants — rather than on data-security failures, which the private right of action polices. And the Delete Act cases show a deliberate escalation: registration failures first, then combined actions, with a strike force announced in November 2025 and an enforcement advisory on inaccurate registrations in September 2026. Our guide to the California Delete Act covers the DROP obligations behind those cases.
What the Agency has actually fined
- Opt-outs that require verification. The regulations prohibit requiring a consumer to verify identity to opt out of sale or sharing; Honda, Todd Snyder and LocateSmarter were all fined for it.
- Asymmetric choices. A privacy management tool that makes accepting easier than declining is a dark pattern; Honda’s was the example.
- Excess information at intake. Asking for more than the statute allows to process a request — down to partial Social Security numbers.
- Broken portals. A technical failure that silently dropped requests for weeks was counted per consumer.
- Missing notices. A privacy policy that did not state the rights, and no notice at collection for job applicants.
- Not registering as a data broker. The cheapest violation to avoid and the most frequently fined.
The private right of action in numbers
The largest of the CCPA penalties is the one regulators do not impose. Section 1798.150 is narrow in scope and large in arithmetic. It applies only to a breach of personal information that is neither encrypted nor redacted, caused by the business’s failure to implement and maintain reasonable security procedures; the consumer must give 30 days’ written notice before claiming statutory damages, and a business that cures within the period and gives a written statement can defeat that claim. But the damages are $107 to $799 per consumer per incident, and class actions multiply them across the affected population: a breach affecting 100,000 Californians carries a statutory-damages range of $10.7 million to $79.9 million before actual damages are considered. It is the reason the CCPA cybersecurity audit regulations, whose first reports fall due in 2028, matter to the litigation budget as much as to the compliance one; our guide to the CCPA cybersecurity audit covers them.
Reducing exposure to CCPA penalties
- Test the opt-out end to end monthly, including Global Privacy Control signals, and log the test; a 40-day silent failure is the Todd Snyder case.
- Remove verification from opt-out and limit requests and cut intake forms to the minimum.
- Make consent tools symmetrical — the same number of clicks to decline as to accept.
- Cover the workforce and applicants with notices at collection and a privacy policy that states the rights.
- Answer the Agency. A subpoena enforcement action against a Fortune 500 company in August 2025 shows that non-response is itself litigated.
- Encrypt and redact, because section 1798.150 does not reach encrypted data, and document reasonable security against the 18 audit components.
Frequently asked questions
What are the CCPA penalties?
Administrative fines by the California Privacy Protection Agency and civil penalties by the Attorney General of up to $2,663 per violation, or $7,988 per intentional violation or violation involving a consumer known to be under 16, since the 1 January 2025 adjustment; statutory damages of $107 to $799 per consumer per incident in private actions over data breaches; and Delete Act fines of $200 per day for data brokers that fail to register or delete.
Is there still a cure period?
Not for regulator enforcement — the 30-day cure period was removed on 1 January 2023. A 30-day notice-and-cure step remains for statutory-damages claims under the private right of action.
What is the largest CCPA fine so far?
The Agency’s $1.35 million decision against Tractor Supply Company on 30 September 2025, for a non-compliant privacy policy and failure to notify job applicants of their rights.
Can consumers sue for any CCPA violation?
No. Section 1798.150 covers only breaches of unencrypted, unredacted personal information caused by a failure to maintain reasonable security; other violations are enforced by the Agency and the Attorney General.
How are violations counted?
The Agency’s decisions treat each affected consumer or request as a violation, so a systemic failure is multiplied by the number of Californians it affected.
Where this leaves you
Budget CCPA penalties as multiplication: the per-violation amount times the consumers affected, tripled for intent or children, with no cure period, and a breach class action at $107 to $799 a head on top. The Agency’s record says where the multiplier is applied — opt-outs, verification, notices, applicants, registration — so test those first, and treat the data broker question as a daily-fine question rather than a definitional one.
References
- California Privacy Protection Agency: updated monetary thresholds in the CCPA (effective 1 January 2025) — The adjusted fine, penalty and statutory-damages amounts and the CPI method.
- CalPrivacy: Tractor Supply decision, 30 September 2025 — The $1.35 million fine and the conduct found.
- CalPrivacy: Honda decision, 12 March 2025 — The $632,500 fine and the opt-out and verification findings.
- CalPrivacy: first action under both the CCPA and the Delete Act, 11 August 2026 — The LocateSmarter decision.
More on the CCPA
- CCPA penalties — you are here
- CCPA compliance in 2026: every new deadline
- California Delete Act and DROP
- CCPA vs GDPR
- CCPA cybersecurity audit
- CCPA service provider vs contractor
The Consumer Request Intake and Verification Procedure, the Right to Opt-Out of Sale/Sharing Procedure, the Privacy Notice Policy, the Data Breach Response Procedure and the CCPA/CPRA Compliance Checklist are in the CCPA-CPRA Compliance Toolkit, or start with the free templates.